BEGIN:VCALENDAR
PRODID;X-RICAL-TZSOURCE=TZINFO:-//Calagator//EN
CALSCALE:GREGORIAN
X-WR-CALNAME:Calagator
METHOD:PUBLISH
VERSION:2.0
BEGIN:VTIMEZONE
TZID;X-RICAL-TZSOURCE=TZINFO:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20170312T020000
RDATE:20170312T020000
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
CREATED;VALUE=DATE-TIME:20170206T223908Z
DTEND;TZID=America/Los_Angeles;VALUE=DATE-TIME:20170425T193000
DTSTART;TZID=America/Los_Angeles;VALUE=DATE-TIME:20170425T180000
DTSTAMP;VALUE=DATE-TIME:20170206T223908Z
LAST-MODIFIED;VALUE=DATE-TIME:20170221T233926Z
UID:http://calagator.org/events/1250471438
DESCRIPTION:Abstract&#13\;\n&#13\;\nNobody really writes their own code a
 ny more\, right? We go out to GitHub and download some libraries for our
  favorite language to do all the hard things for us. Then we download ha
 lf a dozen front end frameworks to make it all pretty and responsive and
  we’re off to the races. In my review I’ve found that more than 90% of t
 he code that makes up an app these days is something we borrowed\, not w
 rote ourselves. Now most of us scan our own code for flaws with Static A
 nalysis tools\, but what about all the stuff we didn’t write? How do we 
 know what’s actually in there? I’ll tell you how to find out and keep tr
 ack of what’s in there\, and how to avoid getting pwned because you let 
 a nasty in the back door with that whiz-bang library that does the reall
 y cool thing you couldn’t live without.&#13\;\n&#13\;\n&#13\;\nSpeaker&#
 13\;\n&#13\;\nJeremy Anderson&#13\;\nCambia Health Solutions&#13\;\n&#13
 \;\nJeremy Anderson is a Secure Software Architect and CSSLP\, with expe
 rience developing software solutions for numerous fortune 500 companies 
 for almost 20 years. In 2014 he had a run in with InfoSec that spurred h
 im into action as an AppSec superhero where he’s worked for HP then Vera
 code. Since early 2016 he’s been working with Cambia Health Solutions\, 
 bootstrapping and scaling an Application Security program from the groun
 d up supporting hundreds of developers for dozens of applications. He’s 
 passionate about not just finding security defects\, but training ninjas
  to destroy them.&#13\;\n&#13\;\n&#13\;\n&#13\;\nThe Open Web Applicatio
 n Security Project (OWASP) is a 501c3 not-for-profit worldwide charitabl
 e organization focused on improving the security of application software
 . To sign up for future meeting notes and to discuss security topics wit
 h local gurus\, sign up on the OWASP Portland mailing list: https://list
 s.owasp.org/mailman/listinfo/owasp-portland&#13\;\n&#13\;\nMeetings are 
 free and open to the public.\n\nTags: security\, owasp\n\nImported from:
  http://calagator.org/events/1250471438
URL:https://www.owasp.org/index.php/Portland
SUMMARY:OWASP: Software Composition -- the other 95% of your app's attack
  surface
LOCATION:New Relic: 111 SW 5th Avenue\, Suite 2700\, Portland Oregon 9720
 4 United States
SEQUENCE:4
END:VEVENT
END:VCALENDAR
